Do Internal Layers of LLMs Reveal Patterns for Jailbreak Detection?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kadali, Sri Durga Sai Sowmya, Papalexakis, Evangelos E.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909833678028800
author Kadali, Sri Durga Sai Sowmya
Papalexakis, Evangelos E.
author_facet Kadali, Sri Durga Sai Sowmya
Papalexakis, Evangelos E.
contents Jailbreaking large language models (LLMs) has emerged as a pressing concern with the increasing prevalence and accessibility of conversational LLMs. Adversarial users often exploit these models through carefully engineered prompts to elicit restricted or sensitive outputs, a strategy widely referred to as jailbreaking. While numerous defense mechanisms have been proposed, attackers continuously develop novel prompting techniques, and no existing model can be considered fully resistant. In this study, we investigate the jailbreak phenomenon by examining the internal representations of LLMs, with a focus on how hidden layers respond to jailbreak versus benign prompts. Specifically, we analyze the open-source LLM GPT-J and the state-space model Mamba2, presenting preliminary findings that highlight distinct layer-wise behaviors. Our results suggest promising directions for further research on leveraging internal model dynamics for robust jailbreak detection and defense.
format Preprint
id arxiv_https___arxiv_org_abs_2510_06594
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Do Internal Layers of LLMs Reveal Patterns for Jailbreak Detection?
Kadali, Sri Durga Sai Sowmya
Papalexakis, Evangelos E.
Computation and Language
Jailbreaking large language models (LLMs) has emerged as a pressing concern with the increasing prevalence and accessibility of conversational LLMs. Adversarial users often exploit these models through carefully engineered prompts to elicit restricted or sensitive outputs, a strategy widely referred to as jailbreaking. While numerous defense mechanisms have been proposed, attackers continuously develop novel prompting techniques, and no existing model can be considered fully resistant. In this study, we investigate the jailbreak phenomenon by examining the internal representations of LLMs, with a focus on how hidden layers respond to jailbreak versus benign prompts. Specifically, we analyze the open-source LLM GPT-J and the state-space model Mamba2, presenting preliminary findings that highlight distinct layer-wise behaviors. Our results suggest promising directions for further research on leveraging internal model dynamics for robust jailbreak detection and defense.
title Do Internal Layers of LLMs Reveal Patterns for Jailbreak Detection?
topic Computation and Language
url https://arxiv.org/abs/2510.06594